Customers managing their own keys can supply two KMS keys: one for the domain, which encrypts the excerpts shown in agent recommendations, and one for content imported from S3, SharePoint Online, Salesforce, ServiceNow or Zendesk; search indices are always encrypted at rest with an AWS owned key.

Checked 2026-10-01

Vendor
Amazon Web Services
Product
Amazon Connect
Subsystem
AI agents encryption
Deployment
multi-tenant
Region
not restricted
Release range
current as of 2026-10-01
Checked
2026-10-01

Sources

Cite this note

APA

WarmTransfer. (2026, October 1). Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-two-kms-keys. WarmTransfer. https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-two-kms-keys

BibTeX

@misc{warmtransfer-claim-amazon-connect-q-setup-two-kms-keys,
  title  = {Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-two-kms-keys},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-two-kms-keys},
  note   = {Source note amazon-connect-q-setup-two-kms-keys, checked 2026-10-01}
}

Read in context